Phishing and Fake Payment Requests: Protecting Egyptian Businesses from Email and WhatsApp Scams
How phishing and business email compromise work, the fake supplier bank-change and WhatsApp manager scams that hit Egyptian companies, and the controls that stop them: a call-back rule, dual approval, SPF, DKIM, DMARC, MFA and training.

The accountant receives an email from a long-standing supplier: "Our bank account has changed, please use the new details for this month's invoice." The logo, signature and tone look right. Or a WhatsApp message arrives from an unknown number with the owner's photo: "I'm in a meeting, transfer 80,000 to this account now and I'll explain later." These are not technical hacks. They are fraud that exploits trust and urgency, and they hit Egyptian companies of every size.
The short answer: protect your business from phishing and fake payment requests with process first and technology second. Never change bank details or send an urgent transfer without calling back on a number you already have. Require two people to approve payments and bank changes. Then protect your email with MFA and publish SPF, DKIM and DMARC records so others cannot easily send mail as your domain. Train staff on real examples.
Key takeaways
- Business email compromise (BEC) is among the most expensive online frauds: the FBI's 2025 internet crime report recorded US$3.05 billion in BEC losses.
- The single most effective control is a call-back rule: verify any bank change or urgent payment by phone, using a number from your own records.
- WhatsApp impersonation of managers works because it is fast and personal; a new number is a red flag, not an excuse.
- SPF, DKIM and DMARC make it harder to impersonate your domain; move DMARC gradually to a reject policy.
- Staff who report a suspicious message quickly are your best detection system, so reward reporting and never punish it.
What phishing and business email compromise are
Phishing is a message, by email, SMS, WhatsApp or social media, that tricks someone into clicking a link, opening a file, entering a password or sending money. Business email compromise (BEC) is the targeted, payment-focused version. The FBI's Internet Crime Complaint Center describes it as "a scam targeting businesses or individuals working with suppliers and/or businesses regularly performing wire transfer payments."
How big the problem is
- The FBI IC3 2025 Internet Crime Report recorded 24,768 BEC complaints with adjusted losses of US$3,046,598,558. These are US complaints, but the same techniques are used against companies everywhere.
- Verizon's 2026 Data Breach Investigations Report found phishing was the initial access vector in 16% of breaches, the human element was present in 62%, and mobile social engineering had a success rate 40% higher than email phishing.
The last point matters in Egypt, where WhatsApp is the de facto business messaging channel: many payment requests and approvals already happen on phones, outside any company system.
The scams Egyptian businesses see most
1. The supplier "changed its bank account"
An attacker either compromises the supplier's mailbox or registers a lookalike domain (for example, one letter different) and replies inside a real invoice thread with new bank details. A factory in 10th of Ramadan paying raw material suppliers monthly is a perfect target: large, regular transfers to known names.
2. The manager on WhatsApp
A message from a new number with the owner's or general manager's profile photo asks for an urgent transfer, gift cards or a confidential document. The excuse is always that they cannot talk now.
3. The fake login page
An email warns that "your mailbox is full" or "a document was shared with you" and links to a fake Microsoft 365 or Gmail sign-in page. Once the password is captured, the attacker reads the mailbox, learns who pays whom, and sets up the next fraud from inside.
4. Fake invoices, shipping notices and payment links
Messages claiming a failed delivery, a customs fee, an e-invoice rejection or an overdue payment, with a link or attachment. For online stores, fake payment confirmation screenshots sent over WhatsApp are a variant.
5. Impersonating your company to your customers
Fraudsters send messages that appear to come from your domain or brand asking customers to pay to a new account. This damages your reputation even though your systems were not touched. Under Article 24 of Egypt's Law 175 of 2018 (Andersen English translation), creating a fake email, website or account falsely attributed to a natural or legal person carries at least three months' imprisonment and/or a fine of EGP 10,000 to 30,000, rising to at least one year and/or EGP 50,000 to 200,000 if it is used to harm that person.
Red flags checklist
| Red flag | Example | What to do |
|---|---|---|
| Request to change bank details | "Please use our new account from this invoice" | Call the supplier on the number in your records; require a second approver |
| Urgency and secrecy | "Transfer today, don't tell anyone yet" | Slow down; urgency is the attacker's main tool |
| New number or new channel | Owner writes from an unknown WhatsApp number | Call the owner's known number before acting |
| Lookalike sender address | Domain with one letter changed, or a free email account | Check the full address, not only the display name |
| Login link in an email | "Your mailbox is full, sign in here" | Open the service by typing its address yourself |
| Unexpected attachment | Invoice or shipping notice you were not expecting | Confirm with the sender through a known channel before opening |
The payment verification rule
Technology cannot tell whether a supplier really changed banks. A written procedure can. Put these rules in writing and have the owner sign them, so staff are protected when they delay a payment to verify it:
- Call back on a known number. Any new or changed bank details, and any urgent or unusual payment request, are confirmed by phone using a number from your supplier file or contract, never a number in the message.
- Two people approve. One person enters a payment or a bank change; another approves it. Our article on user permissions and audit logs in ERP and CRM explains how to enforce this in the system itself.
- Hold new beneficiaries. A first payment to new bank details waits for verification, even if the supplier complains.
- No payment instructions by WhatsApp alone. Transfers need a request through the agreed channel plus verification.
- Tell suppliers and customers your rule. Put a line on invoices and your website: "We will never change our bank details by email or message. Call us to confirm."
SPF, DKIM and DMARC in plain language
These three DNS records help receiving mail systems decide whether an email claiming to come from your domain is genuine. Microsoft Learn defines them this way:
- SPF "specifies the source email servers that are authorized to send mail for the domain."
- DKIM "uses a domain to digitally sign important elements of the message to ensure the message remains unaltered in transit."
- DMARC "specifies the action for messages that fail SPF or DKIM checks for senders in the domain, and specifies where to send the DMARC results (reporting)."
Microsoft notes that "anything less than all of the email authentication methods results in substandard protection", because SPF and DKIM alone do not check that the domain in the visible From address matches; DMARC adds that alignment check.
How to roll out DMARC safely
Microsoft recommends a gradual approach: start with p=none to monitor, move to p=quarantine, then to p=reject, checking reports at each step so legitimate mail (your website's contact forms, invoicing system, newsletter tool) is not blocked. For domains you own but do not use for email, publish a DMARC record with p=reject so nobody can send mail as them. Gmail has also required bulk senders, those sending more than 5,000 messages a day to Gmail addresses, to authenticate their email since February 2024, as Google announced.
If your website, ERP or store sends email through SMTP, make sure that service is included in SPF and signs with DKIM. When we build a business website, contact forms send through an authenticated service rather than an unauthenticated server.
These records protect your domain from being spoofed. They do not stop a real supplier mailbox that has been hacked, which is why the call-back rule comes first.
Protect the mailboxes themselves
- MFA on every mailbox, starting with finance, management and administrators. Prefer an authenticator app or passkeys to SMS; see MFA, passwords and passkeys.
- Watch for forwarding rules. Attackers who get into a mailbox often add a rule that silently forwards or hides supplier emails. Check finance mailboxes for rules nobody created.
- Alerts on unusual sign-ins, such as logins from a new country.
- Separate personal and business WhatsApp for finance staff, and use WhatsApp Business with a known company number for supplier communication.
Training that works
Short, frequent and realistic beats a yearly lecture. Show staff the actual scam patterns above, using your own suppliers' names. Make reporting easy: one WhatsApp group or email address for "is this real?" questions, answered quickly. Thank people who report, including false alarms. If staff also use AI tools that could be fed fake instructions, see AI chatbot security. For a wider programme, the SME cybersecurity 90-day plan places training alongside MFA, backups and access control.
If someone already clicked or paid
- Call your bank immediately and ask it to recall or freeze the transfer; speed matters more than anything else.
- Reset the password and sign out all sessions of any account whose password was entered on a fake page, and check it for new forwarding rules.
- Preserve evidence: the email with full headers, WhatsApp screenshots, the bank reference.
- Warn suppliers and customers who may receive follow-up messages.
- Consider your legal duties: Article 35 of Law 175/2018 penalises a company's actual manager who fails to report a cyber crime against the company's email or systems once aware of it. If personal data was exposed, the 72-hour notification in our breach notification guide may apply.
How Nilex helps
Nilex configures email authentication for the websites and systems we build, sends system email through authenticated SMTP services, and builds approval workflows into ERP payment and supplier modules so a single person cannot change bank details and pay alone. We can also review your domain's SPF, DKIM and DMARC setup.
Frequently asked questions
What is business email compromise?
It is fraud in which attackers impersonate or take over a business email account, often a supplier's or a manager's, to redirect payments or obtain sensitive data. It relies on trust and urgency rather than malware.
How can I tell if a supplier's bank change request is fake?
You often cannot tell from the message itself, because it may come from the supplier's real, hacked mailbox. Always call the supplier on a number from your own records before changing anything.
What should I do if my manager asks for a transfer on WhatsApp from a new number?
Do not send money. Call the manager on the number you already have and confirm. A genuine manager will understand; that is exactly what the rule is for.
Do SPF, DKIM and DMARC stop all phishing?
No. They make it harder for others to send email as your domain, but they do not stop lookalike domains or messages from genuinely hacked accounts. Combine them with the call-back rule, MFA and training.
Is phishing a crime in Egypt?
Law 175/2018 penalises, among other acts, creating a fake email, website or account falsely attributed to a person or company, and unlawful access to email and systems. Consult a lawyer about a specific case.
Want to check whether your domain can be spoofed, or add approval steps to your payments? Talk to us through our contact page.
This article is general information, not legal or tax advice. Confirm the details that apply to your company with a specialist.



